<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Date AND Time Range in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58310#M14253</link>
    <description>&lt;P&gt;Adam,&lt;BR /&gt;
This answer should point you in the right direction.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/61365/getting-logs-for-after-hours-access"&gt;http://answers.splunk.com/answers/61365/getting-logs-for-after-hours-access&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2013 23:09:21 GMT</pubDate>
    <dc:creator>adrianathome</dc:creator>
    <dc:date>2013-09-09T23:09:21Z</dc:date>
    <item>
      <title>Date AND Time Range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58309#M14252</link>
      <description>&lt;P&gt;I'm pretty new to Splunk, so hopefully this is an easy question.  I've looked all over the community questions and I have no problems finding out how to search for ranges of dates OR times, but for the life of me I can't figure out how to do dates AND times.&lt;/P&gt;

&lt;P&gt;Basically I want to search for two EventCodes: 4624 and 4634.  Because there are several thousand results on any given week, my only real concern is WHEN they logged on.  I need to know when these IDs were created between the hours of 1700 and 0500 each day.  I'd like to run this scan weekly, so is there a way to do -7d AND between 1700 and 0500 the next day?  I hope I'm articulating this correctly.  Any help would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;-Adam&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 21:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58309#M14252</guid>
      <dc:creator>whathuh</dc:creator>
      <dc:date>2013-09-09T21:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Date AND Time Range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58310#M14253</link>
      <description>&lt;P&gt;Adam,&lt;BR /&gt;
This answer should point you in the right direction.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/61365/getting-logs-for-after-hours-access"&gt;http://answers.splunk.com/answers/61365/getting-logs-for-after-hours-access&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 23:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58310#M14253</guid>
      <dc:creator>adrianathome</dc:creator>
      <dc:date>2013-09-09T23:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Date AND Time Range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58311#M14254</link>
      <description>&lt;P&gt;I've been looking for that post for an hour since I saw this post.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 23:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-AND-Time-Range/m-p/58311#M14254</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-09-09T23:20:50Z</dc:date>
    </item>
  </channel>
</rss>

